https://teragrep.com
4 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-31866No exploit | Apache Zeppelin: Interpreter download command does not escape malicious code injectionapache · zeppelin · CWE-116 | Critical9.8 | — | 1.4% | Apr 9, 2024 |
27Monitor | CVE-2024-31865No exploit | Apache Zeppelin: Cron arbitrary user impersonation with improper privilegesapache · zeppelin · CWE-20 | Medium6.5 | — | 1.7% | Apr 9, 2024 |
21Monitor | CVE-2024-31863No exploit | Apache Zeppelin: Replacing other users notebook, bypassing any permissionsapache · zeppelin · CWE-290 | Medium5.3 | — | 1.0% | Apr 9, 2024 |
21Monitor | CVE-2024-31862No exploit | Apache Zeppelin: Denial of service with invalid notebook nameapache · zeppelin · CWE-20 | Medium5.3 | — | 1.4% | Apr 9, 2024 |
- CVE-2024-3186639Monitor
Apache Zeppelin: Interpreter download command does not escape malicious code injection
CriticalCVSS 9.8No exploitEPSS 1%apache · zeppelinApr 9, 2024
- CVE-2024-3186527Monitor
Apache Zeppelin: Cron arbitrary user impersonation with improper privileges
MediumCVSS 6.5No exploitEPSS 2%apache · zeppelinApr 9, 2024
- CVE-2024-3186321Monitor
Apache Zeppelin: Replacing other users notebook, bypassing any permissions
MediumCVSS 5.3No exploitEPSS 1%apache · zeppelinApr 9, 2024
- CVE-2024-3186221Monitor
Apache Zeppelin: Denial of service with invalid notebook name
MediumCVSS 5.3No exploitEPSS 1%apache · zeppelinApr 9, 2024